<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:51:45.982357+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-161838</id>
    <title>EUVD-2026-161838</title>
    <updated>2026-10-02T20:51:45.987626+00:00</updated>
    <content>EUVD-2026-161838</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-161838"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45294</id>
    <title>fkie_cve-2024-45294</title>
    <updated>2026-10-02T20:51:45.987657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. Prior to version 6.3.23, XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML. This issue has been patched in release 6.3.23. No known workarounds are available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-45294"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6cr6-ph3p-f5rf</id>
    <title>GHSA-6cr6-ph3p-f5rf — XXE vulnerability in XSLT transforms in `org.hl7.fhir.core`</title>
    <updated>2026-10-02T20:51:45.987688+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.dstu3, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.r4, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.r4b, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.r5, Maven: ca.uhn.hapi.fhir:org.hl7.fhir.utilities</p>
<p>### Impact
XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( `&lt;!DOCTYPE foo [&lt;!ENTITY example SYSTEM "/etc/passwd"&gt; ]&gt;` could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML.</p>
<p>### Patches
This issue has been patched in release 6.3.23</p>
<p>### Workarounds
None.</p>
<p>### References
[MITRE CWE](https://cwe.mitre.org/data/definitions/611.html)
[OWASP XML External Entity Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#transformerfactory)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6cr6-ph3p-f5rf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:6883</id>
    <title>RHSA-2024:6883 — Red Hat Security Advisory: Red Hat Build of Apache Camel 3.20.7 for Spring Boot security update.</title>
    <updated>2026-10-02T20:51:45.987726+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nimbus-jose-jwt: large JWE p2c header value causes Denial of Service undertow: response write hangs in case of Java 17 TLSv1.3 NewSessionTicket undertow: Improper State Management in Proxy Protocol parsing causes information leakage apache: cxf: org.apache.cxf:cxf-rt-rs-service-description: SSRF via WADL stylesheet parameter apache: cxf: org.apache.cxf:cxf-rt-rs-security-jose: Denial of Service vulnerability in JOSE org.hl7.fhir.core: org.hl7.fhir.dstu3: org.hl7.fhir.r4: org.hl7.fhir.r4b: org.hl7.fhir.r5: org.hl7.fhir.utilities: XXE vulnerability in XSLT transforms in `org.hl7.fhir.core`</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:6883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3180</id>
    <title>WID-SEC-W-2024-3180 — Apache Camel und mehrere Red Hat Produkte: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:51:45.987751+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Apache Camel und in mehreren Red Hat-Produkten ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen preiszugeben und beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3180"/>
  </entry>
</feed>
